Imperva has been granted a patent for a computer-implemented method that dynamically enforces a multi-API security policy at runtime. The method involves reading logs of API calls, identifying data objects, assigning data labels, constructing an API call graph, and taking security actions based on policy violations. GlobalData’s report on Imperva gives a 360-degree view of the company including its patenting strategy. Buy the report here.

According to GlobalData’s company profile on Imperva, Network traffic analysis was a key innovation area identified from patents. Imperva's grant share as of February 2024 was 48%. Grant share is based on the ratio of number of grants to total number of patents.

Dynamic enforcement of multi-api security policy at runtime

Source: United States Patent and Trademark Office (USPTO). Credit: Imperva Inc

A recently granted patent (Publication Number: US11916964B2) discloses a computer-implemented method for dynamically enforcing a multi-API security policy at runtime. The method involves reading logs of calls to multiple APIs within a transaction, identifying data objects used by these APIs, assigning specific data labels to data fields, and constructing an API call graph to track the sequence of API calls. By utilizing specific data labels, the method consistently identifies data fields across multiple APIs, enabling the enforcement of a comprehensive security policy that covers various API calls within a transaction. The method also includes logging API calls at runtime, programmatically analyzing data objects, and utilizing linkages between APIs to determine service endpoints.

Furthermore, the patent describes the use of a linear regression model to determine neighbors of service endpoints and the enforcement of security policies to prohibit specific actions concerning identified data fields. The method does not require access to API specifications or code, making it versatile and applicable in various computing environments. By tracking the flow of execution during a multi-API transaction, the method can detect and respond to actions that violate the security policy in real-time. This includes blocking actions that attempt to gain unauthorized access to sensitive data, showcasing the method's proactive approach to ensuring data security within complex API transactions. The patent also covers computer-readable storage mediums and computer systems configured to implement this dynamic enforcement of multi-API security policies, highlighting the practical application of the disclosed method in real-world computing scenarios.

To know more about GlobalData’s detailed insights on Imperva, buy the report here.

Premium Insights

From

The gold standard of business intelligence.

Blending expert knowledge with cutting-edge technology, GlobalData’s unrivalled proprietary data will enable you to decode what’s happening in your market. You can make better informed decisions and gain a future-proof advantage over your competitors.

GlobalData

GlobalData, the leading provider of industry intelligence, provided the underlying data, research, and analysis used to produce this article.

GlobalData Patent Analytics tracks bibliographic data, legal events data, point in time patent ownerships, and backward and forward citations from global patenting offices. Textual analysis and official patent classifications are used to group patents into key thematic areas and link them to specific companies across the world’s largest industries.